Skip to content
Exploit Labs
XPLT · Events · Game of Active Directory

Two days, one complete attack path through Active Directory.

In a hosted multi-domain lab you work from first foothold to full domain compromise, guided by an XPLT operator.

Practice-led: short explanations followed immediately by guided lab execution.

Two editions

Each edition has its own dates, venue and booking page.

Exploit Iceland

Reykjavik

  • 15-16 October 2026
  • 09:00-17:00 GMT
  • English
  • Reykjavik · Regus - Reykjavik
€999
Details and booking
Exploit Dubai

Dubai

  • 5-6 November 2026
  • 09:00-17:00 GST
  • English
  • Dubai · BOCASU
AED 3,999
Details and booking

What you will be able to do by day two

  • Enumerate an unfamiliar Active Directory environment and identify viable attack paths.
  • Use BloodHound and native enumeration to understand domains, trusts, privileges and delegation.
  • Execute Kerberoasting, AS-REP Roasting, password spraying and credential attacks.
  • Exploit relevant NTLM relay, ACL, delegation, GPO and AD CS weaknesses.
  • Chain individual weaknesses into a complete domain-compromise path.
  • Explain the corresponding hardening and detection opportunities to a defensive team.

Isn't GOAD free? Yes.

GOAD is an open-source Active Directory practice lab. You are not paying for access to open-source files. You are paying for a maintained hosted environment, a curated two-day attack path, prepared tooling, direct operator guidance, troubleshooting support and an in-person cohort experience.

Built on the open-source Game of Active Directory project by Orange Cyberdefense and its contributors. View the project.